Security and your data

Your documents, and who can reach them

This page is written for the people who have to sign off the decision: the security officer, the data protection officer, and whoever owns the archive. It sets out plainly what happens to your material, where it is held, who can reach it, and what we do not do with it.

Last updated 9 September 2026

In one page

  • Your own installation. RUNA is not a shared service. Your archive runs in an environment dedicated to your organisation, and no other customer's questions can reach it.
  • No third-party exposure. Your data and your privacy are protected: nothing you put in can reach, or be exposed to, a third party.
  • No training on your material. Your documents are never used to train or improve any model — ours or anybody else's.
  • No external AI provider. The language models are open-weight and run inside the same perimeter as your archive, under our operation. Your questions and documents are not sent to an external AI service.
  • Swiss, physically and legally. A dedicated server in a Swiss high-security facility, operated by a Swiss company under Swiss federal data protection law. No third-country transfer for you to assess.
  • You control what is stored. You decide what goes in, you keep it current, and you can remove documents permanently.
  • Evidence, not assertion. Questions, the sources used and the answers given are recorded, so use of the system can be shown to an auditor rather than described to one.

Download this summary as a two-page PDF — for circulation, security review or a board paper.

Isolation

Your installation belongs to your organisation alone

The common arrangement in this market is a shared platform with a logical partition between customers. That is not what RUNA is. Your organisation receives its own installation: its own virtual machine, its own document store, its own index, its own models running for you.

Nothing is pooled

Your documents are not combined with any other customer's material, and no other customer's questions can reach into your archive.

No third party receives your material

Your documents and the questions asked of them are not passed to an AI provider, an analytics service, or any other external party.

The models run inside your perimeter

RUNA uses open-weight language models that we operate ourselves, alongside your archive. There is no external model call behind an answer.

What "dedicated" means precisely

A virtual machine of your own, on hardware RUNA operates and controls — not a tenancy inside a shared application. Dedicated physical hardware is available where a customer's requirements call for it, on separate commercial terms.

Confidentiality of customers

We do not disclose who our customers are. A customer is named publicly only where they have agreed to it.

Where it runs

Your own environment, inside a Swiss mountain

Your installation runs on hardware RUNA operates in a high-security data centre in Switzerland, built into a mountain. It is not a region of somebody else's cloud with a Swiss label attached — it is equipment we control, in a place with a physical address, a perimeter and a door.

That matters for two separate reasons, and they are worth keeping apart. Physically, the facility is built for material that must not be lost or reached. Legally, RUNA is a Swiss company operating under Swiss federal data protection law, which means your legal colleagues have no third-country transfer to assess and no transfer impact assessment to write.

Hosting
RUNA-operated hardware in a Swiss high-security facility
Operator
RUNA Technologies, a Swiss company
Jurisdiction
Swiss federal data protection law
Isolation
One installation per customer; air-gapped deployment available
Access

Who can reach your installation

Two questions sit behind this heading, and both deserve a straight answer: who inside your organisation can see what, and what access RUNA itself has. We would rather set that out here than have you discover it in a security review.

Inside your organisation

Who may use the installation, and what parts of the archive they may question, is configured with you at deployment and remains under your control afterwards.

RUNA's own access

We operate the installation, so a small number of named RUNA engineers hold administrative access for deployment, maintenance and support. That access is controlled, logged, and defined in the data processing agreement. Nobody at RUNA reads your documents in the course of ordinary operation.

Support with your consent

Where investigating a problem would require sight of your material, we ask first. It is your archive, and access to it for support purposes is your decision to give.

Accountability stays with a named person

Every output of the system is a draft for expert review. RUNA does not decide anything: a named person in your organisation approves the work, and the system supplies the traceability that makes that review quick.

What is recorded

Questions asked, the sources used to answer them and the answers returned are recorded in your installation, so that use of the system can be evidenced to an auditor.

Your data, end to end

What happens to a document, from the day it arrives

  1. You decide what goes in

    You choose which parts of your archive are loaded. Nothing is collected from your systems on its own initiative, and nothing is added without you.

  2. It is processed inside your installation

    Text, tables, scanned pages and the content of graphics are extracted and indexed within your own environment. No part of that processing happens outside it.

  3. It is used to answer your questions, and for nothing else

    Your material is never used to train or improve a model. It does not contribute to answers given to anyone outside your organisation, and it is not analysed for any purpose of ours.

  4. You keep it current

    Documents can be added, replaced when a newer approved version exists, and superseded material can be retired so that it stops influencing answers.

  5. You can remove it permanently

    When you delete a document it is removed from the live system and from the index immediately, and it can no longer appear in any answer. Encrypted backups are held for disaster recovery, and a copy may remain in a backup until that backup is overwritten in the normal cycle. The retention period is stated in your contract.

  6. And at the end of the relationship

    If you leave us, your installation and its contents are deleted on the same terms, and we will confirm it in writing.

Why we state the backup caveat. Every serious provider keeps backups, and a deletion claim that ignores them does not survive its first security review. We would rather write the limit down here than defend a slogan later.
Contracts and compliance

What we sign, and what we will work through with you

Data processing agreement

A data processing agreement under Swiss law forms part of the standard contract, setting out the purposes of processing, the controls, the sub-processors and the deletion terms.

GDPR obligations, voluntarily

Swiss law governs, and we accept the equivalent obligations under the European regime as well — most of our customers must comply with it, and a supplier who does not simply moves the problem to them.

Your questionnaire, answered in writing

Send us your security assessment and we will complete it properly rather than returning a brochure. Where the answer is "not yet", it will say so.

Certification, stated honestly

RUNA does not hold ISO 27001 certification today. We say so rather than implying otherwise, and we are happy to discuss what we do instead, and when that changes.

Air-gapped deployment. For environments where nothing may connect outward at all, an air-gapped installation is available. It is not our standard arrangement and it carries operational consequences worth discussing before anyone commits to it.
Questions we are asked

The ones that come up in every security review

Is our data used to train the model?
No. Not to train, not to fine-tune, and not to improve a model used by anyone else. Your documents answer your questions and do nothing else.
Does any of our material reach an American provider?
No. The models RUNA uses are open-weight and run on our own infrastructure inside the same perimeter as your archive, so there is no call to an external AI service carrying your question or your documents.
Can the system answer from a document the person asking is not allowed to open?
Access to the installation and to the material within it is configured with you at deployment. Bring your permission model to the first conversation and we will walk through it against your own structure rather than in the abstract.
Where exactly is our data held?
On a dedicated RUNA server in a high-security data centre in Switzerland. We will tell you which facility, and under what arrangement, in the first conversation.
What happens if RUNA ceases to exist?
A fair question to ask a young company. Your documents are your own and remain exportable; continuity arrangements are part of the contract discussion, and we would rather have that conversation openly than pretend it never occurs to anyone.
Can we audit you?
Yes, on terms set out in the data processing agreement, at a reasonable frequency.
The next step

Send us your questions

If you are assessing RUNA for your organisation, send us your security questionnaire and we will complete it in writing. If it is easier to talk first, we will arrange an hour with the people who built the system rather than with a sales engineer reading from a script.

Want to know more

Or read how it works.